PaperCut Attacks Target Education Sector
Attackers exploit two PaperCut flaws to steal credentials from schools and universities in the U.S. and Europe.
30 results for “sec”
Attackers exploit two PaperCut flaws to steal credentials from schools and universities in the U.S. and Europe.
New model scores 100% on exploit benchmark, raising enterprise safety questions as OpenAI prepares restricted rollout.
A campaign hides 'funding' lure words with invisible Unicode tags, splitting keywords to slip past filters.
A swarm of 3,700 OpenAI agents made 18,000 wiki posts, discussing sandbox escapes and sharing test answers.
Google patches a high-severity type confusion bug in V8 that has been exploited in the wild, the sixth zero-day fixed this year.
OpenAI pledges $1bn to subsidize Daybreak AI for critical infrastructure defenders.
CNIL fines Hôpital privé de la Loire for security failures that led to a breach exposing data of over 727,000 people.
BraZetsu framework turns compromised Windows machines into commercial inventory for Intermediary access brokers.
The researcher known as Nightmare Eclipse has released FalconFlank, a privilege escalation exploit targeting CrowdStrike Falcon via a Windows Office macro feature.
A 12-year-old PostgreSQL flaw lets low-privilege replication accounts gain superuser access and remote code execution across platforms.
Manchester Airports Group data leak exposes 8.8M records after refusing ransom.
Plex warns users to update Media Server and Desktop clients to fix multiple undisclosed security flaws.
An analyst argues business alignment fails because the CISO role is structurally flawed, proposing a CSO above it.
British legislators propose laws to halt runaway AI systems, citing risks to critical infrastructure.
Autonomous agents strain zero trust's identity limits, experts warn as adoption lags.
A human attacker used AI agents to breach a network in under 10 hours, leaving an 80-page audit.
Dropbox says attackers abused a legacy Lenovo login integration to access 5,000 accounts.
UK rejects extending cyber bill to AI vendors, citing misuse concerns and preferring voluntary safeguards.
OpenAI's Astra model reaches 'Critical' capability level, triggering new safeguards before release.
Sevii's new module autonomously remediates AI-driven attacks at machine speed.
New CG-MCP office centralizes maritime cybersecurity policy as ports face rising operational technology risks.
Palo Alto Networks acquires Console, an AI-native agentic workflow platform, to deepen Cortex's autonomous security capabilities.
CrowdStrike's SafeMind pairs Red Tempest and Blue Solano models for continuous red teaming and autonomous defense.
EFF says Meta's proposed $17 billion settlement fails to protect teens and could harm all users' privacy.
65% of enterprises have seen AI agents act out of scope, with weak detection and authorization gaps.
Russia-aligned UAC-0099 embeds nuclear-weapon-style prompts in a VBS script to misdirect AI-assisted malware analysis, ESET says.
CVE-2026-82329, a critical Artifactory auth bypass, is reportedly under active attack post-disclosure.
Microsoft's false 'Defender off' alerts risk training users to disregard real security warnings, experts say.
Plume research shows SuperBox streaming devices open home networks to malware, despite router placement.
OpenClaw's big update simplifies setup and revamps the UI, but security gaps remain, and critics say the fixes are insufficient.